Cyber Security

Western Digital’s WD Discovery App Flaw Allows Code Execution

The Western Digital Discovery app, a well-known provider of storage devices, has a vulnerability identified as CVE 2024-22169 with a CVSS base score of 7.1 that allows for code execution.

The security vulnerability arises due to the Node.js environment settings in the WD Discovery App. Utilizing the ELECTRON_RUN_AS_NODE environment variable might allow code execution.  

In particular, the vulnerability allows code execution within the context of WD Discovery applications and can be abused by any malicious application running with usual user permissions.

“Any malicious application operating with standard user permissions can exploit this vulnerability, enabling code execution within the WD Discovery application’s context,” the company said.

How to Build a Security Framework With Limited Resources IT Security Team (PDF) - Free Guide

Yoko Kho, AbdulKarim, and Fahad Alamri of the HakTrak Cybersecurity Team were notified of the issue. This vulnerability affects all WD Discovery Desktop App users earlier than 5.0.589. Both Windows and macOS users are impacted by the issue.

Fix Available

Western Digital urges users to upgrade their WD Discovery app to version 5.0.589 or higher on both Windows and Mac devices as soon as possible.

WD Discovery version 5.0.589 addresses this issue by “disabling certain features and fuses in Electron.”

Users can download the most recent version from the WD Discovery Downloads page, accept the update automatically, or follow the directions on the WD Discovery Online User Guide.

Are you from SOC and DFIR Teams? – Analyse Malware Incidents & get live Access with ANY.RUN -> Free Access

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago